SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 104 of 501

CVESummaryPriorityPublished
CVE-2016-1102Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs…EXPLOITHIGH 7.5EPSS 37.2%11 May 2016
CVE-2016-1101Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs…EXPLOITHIGH 7.5EPSS 35.3%11 May 2016
CVE-2016-1096Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs…EXPLOITHIGH 7.5EPSS 37.2%11 May 2016
CVE-2016-1077Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of…EXPLOITCRITICAL 9.8EPSS 15.5%11 May 2016
CVE-2016-4117Adobe Flash Player Arbitrary Code Execution VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 94.4%11 May 2016
CVE-2016-0189Microsoft Internet Explorer Memory Corruption VulnerabilityKEVEXPLOITHIGH 7.5EPSS 94.1%11 May 2016
CVE-2016-0185Microsoft Windows Media Center Remote Code Execution VulnerabilityKEVEXPLOITHIGH 7.8EPSS 69.8%11 May 2016
CVE-2016-0173The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted…EXPLOITHIGH 7.8EPSS 3.53%11 May 2016
CVE-2016-0171The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted…EXPLOITHIGH 7.8EPSS 4.30%11 May 2016
CVE-2016-0170GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document,…EXPLOITHIGH 8.8EPSS 35.0%11 May 2016
CVE-2016-0169GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted…EXPLOITMEDIUM 6.5EPSS 27.8%11 May 2016
CVE-2016-0168GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted…EXPLOITMEDIUM 6.5EPSS 27.8%11 May 2016
CVE-2015-0569Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and…EXPLOITHIGH 7.8EPSS 6.47%9 May 2016
CVE-2016-4535Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted packed executable.EXPLOITHIGH 7.5EPSS 8.22%5 May 2016
CVE-2016-4534The McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on Windows allows local administrators to bypass intended self-protection rules and unlock the console window by closing registry handles.EXPLOITLOW 3.0EPSS 2.73%5 May 2016
CVE-2016-3718ImageMagick Server-Side Request Forgery (SSRF) VulnerabilityKEVEXPLOITMEDIUM 5.5EPSS 76.7%5 May 2016
CVE-2016-3717The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.EXPLOITMEDIUM 5.5EPSS 28.0%5 May 2016
CVE-2016-3716The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.EXPLOITLOW 3.3EPSS 18.9%5 May 2016
CVE-2016-3715ImageMagick Arbitrary File Deletion VulnerabilityKEVEXPLOITMEDIUM 5.5EPSS 75.3%5 May 2016
CVE-2016-3714ImageMagick Improper Input Validation VulnerabilityKEVEXPLOIT ×2HIGH 8.4EPSS 97.5%5 May 2016
CVE-2016-2107The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an…EXPLOITMEDIUM 5.9EPSS 89.1%5 May 2016
CVE-2016-3140The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB…EXPLOITMEDIUM 4.6EPSS 1.55%2 May 2016
CVE-2016-3136The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device without two…EXPLOITMEDIUM 4.6EPSS 1.59%2 May 2016
CVE-2016-2854The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.EXPLOITHIGH 7.8EPSS 0.95%2 May 2016
CVE-2016-2853The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.EXPLOITHIGH 7.8EPSS 0.91%2 May 2016
CVE-2016-2188The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device…EXPLOITMEDIUM 4.6EPSS 1.49%2 May 2016
CVE-2016-1576The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted…EXPLOITHIGH 7.8EPSS 1.13%2 May 2016
CVE-2016-1575The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.EXPLOITHIGH 7.8EPSS 0.92%2 May 2016
CVE-2016-3672The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and…EXPLOITHIGH 7.8EPSS 1.16%27 April 2016
CVE-2016-3139The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device…EXPLOITMEDIUM 4.6EPSS 1.55%27 April 2016
CVE-2016-3135Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE…EXPLOITHIGH 7.8EPSS 1.00%27 April 2016
CVE-2016-3134The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.EXPLOITHIGH 8.4EPSS 0.97%27 April 2016
CVE-2016-2782The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a…EXPLOITMEDIUM 4.6EPSS 1.65%27 April 2016
CVE-2016-2384Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an…EXPLOITMEDIUM 4.6EPSS 3.08%27 April 2016
CVE-2016-2184The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via…EXPLOITMEDIUM 4.6EPSS 1.65%27 April 2016
CVE-2015-7515The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device that lacks endpoints.EXPLOITMEDIUM 4.6EPSS 1.80%27 April 2016
CVE-2016-3081Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.EXPLOITHIGH 8.1EPSS 82.9%26 April 2016
CVE-2016-3074Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.EXPLOITCRITICAL 9.8EPSS 37.0%26 April 2016
CVE-2016-2203The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.EXPLOITHIGH 7.8EPSS 7.77%22 April 2016
CVE-2016-1596Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4)…EXPLOITMEDIUM 5.4EPSS 3.26%22 April 2016
CVE-2016-1595LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the…EXPLOITMEDIUM 6.5EPSS 6.23%22 April 2016
CVE-2016-1594Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.EXPLOITMEDIUM 6.5EPSS 6.62%22 April 2016
CVE-2016-1593Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a ..EXPLOIT ×2HIGH 7.2EPSS 60.2%22 April 2016
CVE-2016-2004HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication.EXPLOIT ×2CRITICAL 9.8EPSS 93.1%21 April 2016
CVE-2016-0891Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remote attackers to hijack the authentication of administrators.EXPLOITHIGH 8.8EPSS 3.91%20 April 2016
CVE-2016-3943Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to gain SYSTEM privileges by…EXPLOITHIGH 7.8EPSS 1.18%18 April 2016
CVE-2015-7378Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local users to gain SYSTEM privileges by modifying Panda_URL_Filteringb.exe.EXPLOITHIGH 7.8EPSS 0.85%18 April 2016
CVE-2016-2417media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process…EXPLOITCRITICAL 9.8EPSS 4.11%18 April 2016
CVE-2016-0846libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider the heap size, which allows attackers to gain privileges via a crafted…EXPLOITHIGH 8.4EPSS 0.98%18 April 2016
CVE-2016-2056xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c.EXPLOITHIGH 8.8EPSS 53.1%13 April 2016

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.